CVE-2025-62179
🟠 Łataj w tym tygodniu
Wstrzyknięcie SQL w WeGIA umożliwia atakującym wykonanie dowolnych poleceń SQL.
CVSS
8.8
EPSS
0.4%
Exploit
poc
Vendor
wegia
Opis źródłowy (NVD)
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/cadastro_funcionario_pessoa_existente.php endpoint, specifically in the cpf parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.5.1.
exploit sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2025-10-13 22:15:32 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 12:10:00 UTC |
Referencje